MyCISO
MyCISO is an Australian cybersecurity SaaS company offering a SecurityOS platform with nine integrated modules for risk, compliance, incidents, suppliers, vulnerabilities, and security culture, serving CISOs and security leaders at government and enterprise organizations.
- Company typePrivate
- Founded2019
- HeadquartersSydney, Australia
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What MyCISO does
MyCISO is an Australian-headquartered SaaS company that builds a unified cybersecurity and governance, risk, and compliance (GRC) platform branded as SecurityOS. Founded in 2019 and based in Sydney with additional offices in Melbourne and Austin (Texas), the platform targets CISOs and security leaders at government and enterprise organizations who need to consolidate risk management, regulatory compliance, incident response, supplier/third-party risk, security culture/awareness, and metrics reporting that would otherwise sit in disconnected spreadsheets, GRC point tools, and board slide decks. The product is organized around nine integrated modules (Assess, Comply, Culture, Incidents, Metrics, Suppliers, Vulnerabilities, Group Accounts, and Risks) underpinned by a proprietary AI engine called PrecogAI that correlates signals across all modules to produce risk-prioritized improvement roadmaps, cross-framework control mapping across 65+ standards, and automated board-ready reporting. PrecogAI supports predictive analytics, knowledge retrieval/cross-module correlation, process automation, and anomaly detection across structured data and text generated outputs.
The platform ingests telemetry from 550+ third-party applications via APIs and webhooks, including Microsoft 365, Azure AD/Entra ID, AWS Security Hub, Google Workspace, CrowdStrike, Qualys, Tenable, Rapid7, Splunk, ServiceNow, Jira, Slack, Microsoft Teams, Okta, Nessus, and SentinelOne, allowing customer environments to feed live vulnerability, identity, and configuration data into the unified risk model. MyCISO monetizes through tiered annual subscriptions (Platform self-service starting around $2,000/year, three bundle tiers — Essentials, Core, Enterprise — scaled by organization size up to ~$15,000/year) layered with three service tiers (Platform self-service, Plus "Done With You" with assigned consultants, and Elite "Done For You" with a dedicated virtual CISO on outcomes-based commercial terms). Go-to-market is primarily direct enterprise field sales anchored on website demo requests, with thought leadership content (ROI calculator, security metrics guide) and event presence including RSAC 2026 in San Francisco. The company is privately held, founder-led (Mike Saxton, Dane Meah, Shaun Redman), appears bootstrapped with no disclosed external funding rounds, and counts more than fifteen named enterprise customers across Australian healthcare, retail, financial services, education, nonprofit, and government verticals including Domino's, David Jones, NSW Health, Australian Red Cross, University of Queensland, and the Australian Department of Justice.
MyCISO firmographics
Firmographics- Name
- MyCISO
- Legal name
- MyCISO
- Website
- https://myciso.co
- Company type
- Private
- Founded year
- 2019
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- MyCISO is an Australian cybersecurity SaaS company offering a SecurityOS platform with nine integrated modules for risk, compliance, incidents, suppliers, vulnerabilities, and security culture, serving CISOs and security leaders at government and enterprise organizations.
- Ownership category
- akta.pro rank
MyCISO industry classification
Industry- Product category
- Cybersecurity GRC Software
- NAICS
- Computer Systems Design and Related Services (54151), Computer Systems Design Services (541512), Computer Systems Design and Related Services (5415)
- SIC
- Services-Computer Integrated Systems Design (7373), Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Cybersecurity Architecture & Security Integration (BPAEAAAL)
- akta.pro secondary industries
- Security Architecture & Engineering Advisory (Zero Trust, IAM, Network) (BPAKADAF), Security Management Platforms Integration (PSIM/SOC, Command & Control) (BPAKAGAH)
Keywords
Where MyCISO is headquartered
LocationHeadquarters
- HQ city
- Sydney
- HQ country
- Australia
- HQ region
- Oceania
Offices3 records
Markets served
MyCISO business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Operations, Infrastructure
Revenue model
- Platform Subscription: Subscription-based pricing for access to the MyCISO SecurityOS platform. Pricing tiers based on organisation size: Small (1-50 employees) from ~$3,000/year, Small-Medium (51-200) from ~$6,000/year, Medium (201-500) from ~$7,500/year, Medium-Large (501-1,000) from ~$10,000/year, Enterprise (1,001+ employees) from ~$15,000/year. All pricing when purchased as part of a complete bundle.
- Service Tiers - Plus (Done With You): Done With You tier adding assigned security consultant, quarterly strategy sessions, gap analysis and remediation planning, board reporting assistance, framework implementation guidance, and priority support. Builds on Platform tier.
- Service Tiers - Elite (Done For You): Outcomes-based engagement with dedicated virtual CISO, full program management, continuous compliance monitoring, supplier risk management, incident response coordination, custom integrations and automation, executive and board presentations, and measurable outcome guarantees.
- Bundle Packages: Three bundle tiers: Essentials (for SMEs with essential frameworks, vulnerability scanning, metrics), Core (full 65+ frameworks, group accounts, compliance module, internal/external scanning), and Enterprise (full suite with incident management, 35+ playbooks, 20 supplier assessments, Level 4 vulnerability scanning).
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Annual | Platform - Self-Service tier with full platform access |
| Subscription | Annual | Plus - Done With You with dedicated consultants |
| Outcome Based/ Performance | Annual | Elite - Done For You with outcomes-based engagement |
| Subscription | Annual | Essentials bundle for SMEs |
| Subscription | Annual | Core bundle - Most Popular |
| Subscription | Annual | Enterprise bundle - Full Suite |
Go-to-market motion1 record
Distribution channels4 records
Marketing channels5 records
MyCISO product offering
Product offeringCore offering
MyCISO provides a unified Security Operating System (SecurityOS) that consolidates security program management across risk, compliance, incidents, suppliers, metrics, and culture into a single AI-powered platform. It serves CISOs and security leaders at SMEs through large enterprises with cross-framework control mapping (65+ frameworks), real-time program visibility, board-ready reporting, and a proprietary AI engine called PrecogAI that correlates signals across modules to deliver risk-prioritised improvement strategies.
Product overview
MyCISO offers a SecurityOS platform architecture combining a unified core platform with nine integrated modules: Assess (maturity assessment against 65+ frameworks), Comply (compliance automation and certification), Culture (security awareness and training), Incidents (incident response with 35+ playbooks), Metrics (KPI tracking and board reporting), Suppliers (third-party risk management), Vulnerabilities (continuous scanning and risk profiling), Group Accounts (multi-entity consolidation), and PrecogAI (AI-powered predictive intelligence engine). The platform is offered through three service tiers (Platform self-service, Plus done-with-you, Elite done-for-you) and three bundles (Essentials, Core, Enterprise) priced by organization size starting from approximately $3,000/year per module.
Differentiator
Problem solved
Functional benefit
Products and services
- SecurityOS Platform Unified Security Operating System that consolidates governance, risk, compliance, resilience, supplier risk, incidents, metrics, and culture management into one intelligent platform with real-time visibility and board-ready reporting for CISOs and security leaders.
- PrecogAI
- Assess Module Security maturity assessment module that tracks, prioritises and uplifts security programs with continuous, evidence-based scoring against 65+ frameworks including ISO 27001, NIST CSF, and Essential Eight.
- Comply Module Compliance management module that simplifies audits, automates evidence collection, and supports certification across ISO 27001, SOC 2, ISO 42001, and ASD ISM with cross-framework control mapping.
- Culture Module Security culture and awareness module that drives behavioural change through targeted training, phishing simulations, engagement analytics, and role-based content delivery to measure and improve human risk.
- Incidents Module Incident response management module with 35+ playbook templates, tabletop exercise capabilities, live incident tracking with audit trails, and post-incident review workflows aligned to ISO 27035 and NIST standards.
- Metrics Module Security metrics and KPI tracking module that automates data collection from across the platform, provides trend analysis, threshold alerts, and generates board-ready metric reports with benchmark comparisons.
- Suppliers Module Third-party supplier risk management module that assesses, monitors, and improves supplier security posture through automated questionnaires, dynamic criticality scoring, improvement plans, and continuous vulnerability scanning.
- Vulnerabilities Module Continuous vulnerability and risk profiling module that detects, prioritises and resolves exposures through external and internal scanning, mapping 250+ data points to control frameworks for indicators of maturity.
Quantifiable outcome
- 87% cost reduction vs traditional consulting delivery
- +2 more outcomes
Companies that use MyCISO
Customer profileNamed customers17 records
Segments3 records
Ideal customer profiles3 records
MyCISO technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration17 records
AI capability6 records
Feature5 records
MyCISO partnerships and signals
Strategic signalPartnerships
Eight partnerships are on record, tiered core.
- Microsoft 365coreIntegration with Microsoft 365 productivity suite as part of the 550+ app integration ecosystem. Enables data synchronisation and security signal correlation for PrecogAI intelligence engine.
- Azure AD / Entra IDcoreIntegration with Azure Active Directory / Microsoft Entra ID for identity and access management data feeds into the PrecogAI engine.
- AWS Security HubcoreIntegration with Amazon Web Services Security Hub for cloud security posture data aggregation and analysis.
- CrowdStrikecoreIntegration with CrowdStrike endpoint protection platform for security telemetry and vulnerability data.
- Google WorkspacecoreIntegration with Google Workspace productivity suite for security signal correlation and user activity monitoring.
- ServiceNowcoreIntegration with ServiceNow ITSM platform for workflow automation and incident management data synchronisation.
- SplunkcoreIntegration with Splunk SIEM platform for log analysis and security event correlation data feeds.
- JiracoreIntegration with Jira project management tool for tracking security tasks, remediation items, and workflow management.
Scale indicators8 records
Recent moves6 records
Expansion highlights6 records
MyCISO competitors and assessment
Company assessmentDirect peers
- Vanta: Vanta is a leading automated compliance and GRC platform that helps organizations achieve and monitor SOC 2, ISO 27001, HIPAA, and other certifications. Directly competes with MyCISO in the mid-market compliance automation segment, with overlapping framework coverage, self-serve motion, and auditor-network integrations.
- Drata: Drata provides continuous compliance automation across frameworks like SOC 2, ISO 27001, and HIPAA, with auditor integrations and automated evidence collection. Closely comparable to MyCISO on automated evidence collection, framework support, and SMB-to-enterprise GTM.
- AuditBoard: AuditBoard is a cloud-based platform for audit, risk, and compliance management with strong enterprise penetration. Competes with MyCISO on risk and compliance management for mid-to-large organizations, particularly for SOX-adjacent and enterprise audit programs.
- Hyperproof: Hyperproof provides continuous compliance and security assurance with framework support and automated evidence collection. Closely comparable to MyCISO's Comply and Assess modules for mid-market customers.
- Secureframe: Secureframe offers compliance automation and security program management with framework templates, integrations, and audit support. Competes with MyCISO in the SMB/mid-market compliance and security program management category, particularly in North America.
- Resolver: Resolver (now part of Kroll) provides integrated risk, compliance, and incident management software. Comparable to MyCISO across risk management, compliance tracking, and incident response modules, with broader incident management heritage.
- LogicGate Risk Cloud: LogicGate offers a no-code GRC platform for risk, compliance, and third-party risk management. Directly comparable to MyCISO's risk, compliance, and supplier modules with similar mid-market and enterprise targeting.
Broad incumbents
- ServiceNow GRC: ServiceNow's Integrated Risk Management and GRC products are embedded in enterprise ITSM deployments and compete with MyCISO's risk, compliance, incident, and supplier modules. Operates as a much larger, broader platform incumbent targeting enterprise CISOs.
- OneTrust: OneTrust is a broad GRC and trust intelligence platform covering privacy, security, ethics, ESG, and third-party risk. Larger incumbent operating across multiple GRC domains that overlap with MyCISO's risk, compliance, and supplier risk modules.
Emerging players
- Scrut Automation: Scrut Automation is an emerging GRC platform focused on risk observability and continuous compliance for cloud-native organizations. Comparable emerging player with overlapping risk and compliance automation value propositions, though with a smaller integration footprint than MyCISO.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat6 records
Key risks6 records
Key highlights7 records
Customer concentration
MyCISO social profiles
Digital presenceMyCISO compliance and trust
Trust signalCompliance11 records
MyCISO financial estimates
Financial estimateRevenue estimate
Valuation estimate
MyCISO leadership team
Management profileNumber of profiles
Profiles3 records
MyCISO funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
MyCISO M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about MyCISO
What does MyCISO do?
MyCISO provides a unified Security Operating System (SecurityOS) that consolidates security program management across risk, compliance, incidents, suppliers, metrics, and culture into a single AI-powered platform. It serves CISOs and security leaders at SMEs through large enterprises with cross-framework control mapping (65+ frameworks), real-time program visibility, board-ready reporting, and a proprietary AI engine called PrecogAI that correlates signals across modules to deliver risk-prioritised improvement strategies.
Is MyCISO a public or private company?
MyCISO is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was MyCISO founded?
MyCISO was founded in 2019. It employs 11 to 50 people.
Where is MyCISO based?
MyCISO is headquartered in Sydney, Australia, in the Oceania region.
How does MyCISO make money?
Four revenue lines are on record. Platform Subscription is the primary driver. The others are service Tiers - Plus (Done With You), service Tiers - Elite (Done For You) and bundle Packages.
Who are MyCISO's main competitors?
Direct peers on record are Vanta, Drata, AuditBoard, Hyperproof, Secureframe, Resolver and LogicGate Risk Cloud. Broad incumbents are ServiceNow GRC and OneTrust. Scrut Automation is listed as an emerging player.
Does MyCISO have an API?
Yes. REST API and webhook integrations available. The platform supports syncing with 550+ apps and tools. API connectors are available as part of bundles: Essentials includes API connector x 1, Core includes API connector x 1, and Enterprise includes 3x API connectors.
What industry is MyCISO in?
MyCISO's product category is Cybersecurity GRC Software. Its primary akta.pro industry code is BPAEAAAL, Cybersecurity Architecture & Security Integration, with a secondary code of BPAKADAF, Security Architecture & Engineering Advisory (Zero Trust, IAM, Network). Its NAICS code is 54151 and its SIC code is 7373.